There is a reason that most data breach incidents involve phishing attacks: phishing works. Attackers know that it is far easier to gain access to a protected network by tricking people into clicking on malicious links and attachments than it is to penetrate sophisticated firewalls and intrusion detection systems. And they know that they have an edge over the defenders because they only have to win once to gain access. As defenders, we need to stop them every time. We can’t prevent attackers from soliciting people with phishing emails. But we can take away their edge.